Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions IMPLEMENTATION_PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,8 @@ MPRC can open a race or merchandise item for sale only when the platform can:
9. Do not trade payment integrity for UI responsiveness. Confirmation may say “processing”; it must not guess “paid.”
10. Legal/tax/insurance questions are escalated to qualified owners, not decided by an implementation agent.

**WEB-002D pending release boundary:** [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one active exact-artifact Netlify exception under review and is not published. It projects only the released #291 visible-focus behavior, #490 deterministic phone-menu disclosure/close behavior, and merged #657 route-focus handoff onto live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. Pinned source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7` must match an exact two-parent merge whose first parent is `95880748e15c03b0ee58da6e1ed11ac6c9526529`. Until the exact preview, signed-out public checks, and immediate repause all pass, #623 deploy `6a7e072f8f346b0008510d29` remains production and the rollback target. #659 does not publish accumulated `main`, deploy Firebase, configure a provider, use an account, change production data, or connect the directory. Directory availability stays literal `false`; reusable hosting remains open under #460/#133/#136.

## 3. Dependency map

```mermaid
Expand Down
2 changes: 2 additions & 0 deletions OFFICER_START_HERE.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,8 @@ Use the club's approved password manager for access. Share only a public link or

As of **2026-08-13**, a merge runs checks but does not start the GitHub release. The protected release is **NOT AVAILABLE YET** until its short-lived cloud identity and named environment approvers are configured under issue #133. Ordinary Git-triggered Netlify production builds are paused. An overbroad #473 web artifact was published and immediately rolled back; its bounded replacement remains the recorded rollback. #623 then completed one separate, exact-artifact release of the inert member-directory interface. Netlify deploy `6a7e072f8f346b0008510d29` is live from source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. Signed-out route and guard checks passed, no member-directory request was observed, and repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` made the temporary manifest inactive without replacing that deploy. Shop remains the static in-person catalog, while Events and Calendar show a fixed retry-later notice instead of a raw provider error. Event records are still unavailable because no Firebase repair was deployed. This does not change sign-in, expose protected event offers, add officer editing, or make commerce safe. GitHub Pages still reports `runmprc.com` as its custom domain even though Netlify serves that name; source removal is not provider proof. A green test or workflow does **not** by itself prove that GitHub Pages, `runmprc.com`, Firebase, or that domain setting changed.

As of **2026-08-14**, [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one accessibility-only Netlify release under review and is not published. It pins one frozen 62-file artifact from source `7496fe0881fb52908c4ff2f40f488df09c94c908` and combines only the reviewed visible keyboard focus, phone-menu close/disclosure, and client-side route-focus behavior. Production remains #623 deploy `6a7e072f8f346b0008510d29`, which is also the rollback target. Officers do not run commands, sign in, enter data, change Firebase or a provider, or approve this as a reusable release. A named observer may perform the safe signed-out browser checks only after the platform owner supplies the exact preview, marker, and approval record. Follow [Review, merge, release, and check a change](./docs/officers/PUBLISH_AND_CHECK.md) and stop on any mismatch.

The optional profile-photo and officer People-finder functions are still **NOT AVAILABLE YET**. #621 makes the frontend default an inert preview: My Account shows the future photo and separate finder-choice controls disabled, while the People finder stays behind the administrator guard and shows its name field and Search button disabled. The preview reads no saved photo or setting, accepts or uploads no photo, searches no name, and saves nothing; it shows no people or sample results. #623 published exactly that disabled interface as deploy `6a7e072f8f346b0008510d29`. Officers inspect the protected layouts only in synthetic local artifacts. The completed signed-out production review proved only the exact revision, normal sign-in and administrator guards, and absence of a member-directory network request. Do not sign in to production, choose a real photo, enter a real name, or treat the preview as a directory. #623 changed no Firebase, provider configuration, account, sign-in, or production data. #507 must later prove the privacy, authorization, staging, backend-first deployment, and readback gates before a separate reviewed source change may connect it. Follow the preview and source-review procedure in [Events, shop, members, and money](./docs/officers/EVENTS_SHOP_MEMBERS.md).

For the concise handbook, see [OFFICER_HANDBOOK.md](./OFFICER_HANDBOOK.md). The expanded task index is [docs/officers/README.md](./docs/officers/README.md).
2 changes: 2 additions & 0 deletions OPERATIONS_RUNBOOK.md
Original file line number Diff line number Diff line change
Expand Up @@ -691,6 +691,8 @@ WEB-002A [#473](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/473) compl

WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) completed its bounded inert member-directory interface release on 2026-08-13. Pinned Deploy Preview `6a7e05febf8fde00084cf9e0` matched release-control head `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`, and PR CI run `31728469418` passed. Exact two-parent merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d`, parents `019353361210021483f23003e09ee6924b78e67c` and `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`, tree `41b6d024d369d93f28ea49940b4f4e5710d3ab52`, passed exact-main CI run `31728908486`. Netlify deploy `6a7e072f8f346b0008510d29` became ready and published at `2026-08-13T18:05:35.983Z`. Its marker matched frozen source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`, previous source `39ab8649df411262c8109a3c81a57bc38f1e168b`, rollback deploy `6a6dc9ea588b0c0008036312`, 62 files, and digest `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1`. Signed-out `/account` and `/admin/member-directory` checks retained the normal guards; route and bundle review found no connected member-directory symbol or request. Protected Account and administrator layouts remain proved only with synthetic local artifacts. Repause head `d401daa409176dce0906c245adf3f20310cb513b` passed PR CI run `31728977578`; exact two-parent repause merge `c8678c623afdd9becf77d596b71f36f26f04b746`, parents `9d5cc8612b4321172370bd949d307e7e4ac0ec7d` and `d401daa409176dce0906c245adf3f20310cb513b`, passed all five exact-main jobs in run `31729248865`. Its Netlify attempt `6a7e081e73fdd60009f7ba57` errored unpublished; provider and marker readback retained deploy `6a7e072f8f346b0008510d29`. The manifest is inactive, the release source ref is absent, and rollback ref `codex/netlify-source-623-rollback` remains. #623 deployed no Firebase, Rules, Functions, or indexes; changed no outside-provider configuration, account, sign-in, or production data; and made no connected directory behavior available. Connected behavior remains **NOT AVAILABLE YET** under [#507](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/507). Do not reuse this exception as a general release button.

WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is an active one-shot Netlify accessibility release under review and is not published. Release ID `WEB-002D-KEYBOARD-FOCUS-2026-08-14` pins remote source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and artifact digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; the exact six-path diff from previous/current live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec` has digest `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. The manifest expects exact first parent `95880748e15c03b0ee58da6e1ed11ac6c9526529`, release branch `codex/issue-659-netlify-release`, source ref `codex/netlify-source-659-keyboard-focus`, and rollback deploy `6a7e072f8f346b0008510d29`; rollback ref `codex/netlify-source-659-rollback` pins the current live source. The frozen source changes only `src/App.jsx`, `src/App.test.jsx`, `src/components/Navbar.jsx`, `src/components/ScrollToTop.jsx`, `src/headerClearance.test.jsx`, and `src/index.css`, combining exact reviewed #291 visible focus, #490 phone-menu disclosure/close behavior, and #657 path-navigation focus. Until the pinned preview, exact two-parent merge, production marker, signed-out desktop/phone focus and menu checks, and immediate repause all pass, #623 deploy `6a7e072f8f346b0008510d29` remains production and the rollback target. Stop for any source, tree, path, count, artifact, parent, marker, focus, menu, network, or repause mismatch. #659 has no authority for Firebase, Rules, Functions, indexes, outside-provider configuration, accounts, sign-in, production data, content, routes, payments, or connected directory behavior; directory availability remains literal `false`. Follow the pending no-terminal procedure in `docs/officers/PUBLISH_AND_CHECK.md`; never use this exception as a general release button.

Incident record: on 2026-08-01, overbroad source `094af1096ed8721597561cd59bf695d4c4a9d210` was published by merge `40728ff6141e34a279b70cc41d983c22ac5f0daa` as deploy `6a6dc0167fbe68000816b448` after a release-blocker comment. Exact rollback merge `1099ee8e6fdb81141fd9460de175b6d854cbcfdd` published deploy `6a6dc219a8136300081811db`, restoring source `ed1b0833`, tree `878c6628d961f4484cb49208aef53f1e9f2e3b47`, 60 files, and digest `7570955c2a00926e5813aef135f1799172cfd046072ac89fb4e492bed0797092`. Safety merge `dee79511b6e371329aa129139729e112e7a51aad` re-paused the manifest; its Netlify attempt `6a6dc35767a4ef000877e74b` did not publish, and provider readback left the rollback deploy live. The overbroad release ref was deleted and verified absent. This incident changed no Firebase, outside-provider configuration, account, payment, or production data.

### Production approvals
Expand Down
1 change: 1 addition & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,7 @@ The findings below describe the repository at the start of the 2026-07-12 assess
| RISK-034 | Webhook error response includes the Stripe library's signature error detail. | Return generic client errors; keep sanitized structured diagnostics server-side. |
| RISK-035 | The deterministic frontend Jest suite and standalone SPA callback suite run as separate blocking hosted CI steps. CI-001B4/#186 merged a non-mutating frontend lint gate as `bec7d5e365eacb418563a172029f241f660d9768`; exact PR and post-merge runs passed. CI-001B4A [#227](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/227) removes one reviewed `arrow-body-style` error, CI-001B4B [#239](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/239) removes one stale `AdminMembers` unknown-rule suppression record, and PAY-004C1 [#359](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/359) retires one `no-alert` warning plus two label-association errors with the unsafe reusable-link controls. Reviewed functional changes in [PR #391](https://github.com/Run-MPRC/Run-MPRC.github.io/pull/391) and [PR #392](https://github.com/Run-MPRC/Run-MPRC.github.io/pull/392) add one and two TypeScript files respectively while retiring two TSX errors each. CI-001B4C [#449](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/449) replaces the four remaining stale `react-hooks/exhaustive-deps` directives with ordinary same-line comments, without changing executable code or the gate. MEMBERS-CONTENT-001B [#492](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/492) removes one finding-free dormant JSX file. MEMBERS-DIRECTORY-001A [#505](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/505) adds four finding-free TypeScript/TSX files, MEMBERS-DIRECTORY-001B [#506](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/506) adds four more, WEB-SUGGESTIONS-001A [#618](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/618) adds one finding-free JSX page, and MEMBERS-DIRECTORY-001D [#621](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/621) adds one finding-free TypeScript availability module. The current baseline scans 120 files and still records 113 configured errors and 6 warnings after the lint process disables the repository's severity-masking `eslint-plugin-only-warn` hook. Branch protection, remaining lint-debt cleanup, and broader domain/integration coverage remain incomplete. | Continue reducing the reviewed finding baseline in focused changes, prove required branch checks, and add domain/integration coverage. Never regenerate the baseline merely to make CI green. |
| RISK-036 | #135 adds a manual exact-commit source gate, fixed profile-recovery targets, backend-first order, missing-config failure, and ordinary Git-triggered Netlify production containment. WEB-UX-001A [#457](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/457) used a temporary exact-artifact exception. On 2026-08-01 an overbroad WEB-002A artifact was merged after a late blocker and published; exact rollback merge `1099ee8` restored source `ed1b0833`, and `dee7951` paused the manifest. Bounded replacement [#473](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/473) then published exact source `39ab8649` as deploy `6a6dc9ea588b0c0008036312`; its delta is only Shop and Events/Calendar failure containment, and its public checks passed. Final control `cb6a8f0` made the manifest inactive; Netlify attempt `6a6dcdd47bc81e000859a249` stopped unpublished and left that bounded deploy as #623's rollback. WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) then completed one exact-artifact release: merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d` published frozen inert source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`, 62 files, and digest `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1` as deploy `6a7e072f8f346b0008510d29`. Signed-out marker, route, guard, and no-connected-symbol/request checks passed. Repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` made the manifest inactive; attempt `6a7e081e73fdd60009f7ba57` stopped unpublished and retained the verified deploy. The release source is absent and the rollback ref remains. Protected environments/OIDC, isolated staging, a reusable live-Netlify path, and provider-owned atomic rollback remain unverified. | Require a final blocker re-read and an executable delta from the live artifact before every release merge. Preserve the exact #473 rollback evidence, keep ordinary publication paused, and keep the reviewed Git rollback projection available. Treat #623 as a completed one-off, not a reusable control. Complete #133 and #136, provision isolated staging, protect the reusable Netlify release path under WEB-001, and rehearse provider rollback before broader production work. |
| WEB-002D pending exact-artifact containment for RISK-036 | [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is an active accessibility-only release under review and is not published. Its frozen source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7` project only reviewed #291 visible-focus, #490 phone-menu, and #657 route-focus behavior over live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. The exact six-path diff digest is `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. Production remains #623 deploy `6a7e072f8f346b0008510d29`, which is also the rollback target. Literal-false directory availability, Firebase, providers, accounts, sign-in, production data, and connected directory behavior are unchanged. | Require the pinned preview, exact parent `95880748e15c03b0ee58da6e1ed11ac6c9526529`, exact two-parent merge, signed-out marker/focus/menu checks, separately reviewed rollback, and immediate repause. Stop for any source, tree, scope, count, digest, parent, marker, focus, menu, directory-request, backend, provider, account, data, or repause mismatch. Treat #659 as one temporary exception, not reusable authority. Preserve active #616 OAUTH-001A2L files and its RISK-024 wording byte-for-byte. |
| RISK-037 | Account/registration deletion, export, retention, backup, and restore procedures are incomplete. | Approve retention matrix, automate minimization, support access/deletion requests, and test backup restoration. |
| RISK-038 | Source-controlled secret scan is ad hoc; no continuous secret scanner, dependency update bot, SBOM, provenance, or branch protection is documented. | Add secret/dependency/code scanning, reviewed lockfile updates, protected environments/branches, and artifact provenance appropriate to project scale. |
| RISK-039 | Some authenticated accounts can lack `members/{uid}` after the Firebase cutover; the account screen hid the read failure and exposed an update that could only fail. Manual database/account repair could corrupt roles or private data. | Use an authenticated create-once server bootstrap, keep browser creation denied, fail the UI closed, and prove backend-first deployment with synthetic accounts. |
Expand Down
Loading